SShortSingh.
Back to feed

NVIDIA Launches OpenShell to Sandbox AI Agents and Enforce Access Policies

0
·2 views

NVIDIA has released an open-source project called OpenShell, designed to provide a secure, isolated runtime environment for autonomous AI agents. The tool addresses risks such as credential leaks, prompt injection, and unintended system commands by running each agent inside its own sandbox with kernel-level controls. A built-in policy system lets developers define exactly which files, network hosts, and system calls an agent may access, with a gateway enforcing those rules at runtime. OpenShell supports Linux, macOS on Apple Silicon, and Windows via WSL 2, and requires Docker, Podman, or host virtualization to operate. SDKs are available for Python, TypeScript, Go, and Rust, allowing developers to integrate OpenShell into their own applications.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Modern scroll-driven animations: separating entry/exit with robust CSS fallbacks

A modern approach to scroll-driven web animations recommends splitting entry and exit effects into two separate animations rather than combining them in a single keyframe block. This separation allows independent control of easing, timing, and transforms, reducing layout bugs across different screen sizes and dynamic content. The technique leverages native CSS properties like animation-timeline: view() and animation-range, anchoring animations to semantic scroll ranges instead of fragile manual percentage calculations. Because browser support for scroll-driven animations is not universal, developers are advised to implement feature detection and fall back gracefully to the Intersection Observer API where needed. The overall approach prioritizes resilience, accessibility, and declarative CSS intent over geometry-dependent workarounds.

0
ProgrammingDEV Community ·

Wrium is a lightweight reactive JavaScript library that needs no build tools

A developer has released Wrium, a small open-source JavaScript library designed to bring reactivity to web interfaces without requiring a bundler or compiler. Users simply add a script tag to an HTML file and use Vue-inspired directives such as v-if, v-for, and v-model to bind data to the page. When data changes, Wrium automatically updates the relevant parts of the UI, eliminating the need to manually query and modify DOM elements. The library weighs approximately 10.9 KB minified, has zero dependencies, and ships with TypeScript declarations under the MIT license. Wrium is positioned not as a replacement for large frameworks but as a lightweight alternative for projects where full-scale tooling is unnecessary.

0
ProgrammingDEV Community ·

Developer Builds Flask Coupon Calculator to Solve Real Cashier Math Challenges

A developer and cashier created a lightweight Flask web app called Coupon Calculator to simplify discount calculations at checkout. The project was motivated by the creator's personal struggle with dyscalculia, which makes mental math difficult during busy retail shifts. The app allows users to enter an original price and apply either a percentage or fixed discount, then instantly view the savings and final price. It includes input validation, protection against negative values, and currency-safe rounding to two decimal places. The tool was built as a practical, everyday solution and is available as a live web app.

0
ProgrammingDEV Community ·

Security Audit Flags 9 Vulnerabilities in $3.4B USDT0 Stablecoin Contracts

A DeFi security research team conducted a surface-level audit of USDT0, a cross-chain stablecoin with $3.45 billion in total value locked across Ethereum and Layer-2 networks including Arbitrum, Optimism, and zkSync. The audit, dated September 30, 2026, identified nine distinct attack vectors and assigned the protocol an overall risk score of 7.4 out of 10, categorized as High. The most critical findings include overly centralized admin privileges, an upgradeable proxy with an unprotected admin slot, and mint/burn functions whose access controls can be modified by the contract owner. Reviewers also flagged a governance timelock that can be bypassed via an executeImmediate() function, and cross-chain bridge signature handling vulnerable to replay attacks. While the codebase relies on audited OpenZeppelin libraries, researchers concluded that centralization of authority and bridge signature management represent the most exploitable weaknesses in the current deployment.